e30c3b632a
Forges (multi-host) + tokens, project directories, and git identity now live in a private SQLite config store (internal/store, modernc.org/sqlite) on a /data named volume that is not bind-mounted or exposed, so credentials aren't reachable outside the container. New Settings page (/settings) + <settings-panel> with /api/config CRUD. Scanner reads roots fresh from the store each cycle; service resolves forges per-repo from the store and reapplies per-forge git auth on change. First run seeds the store from .env. Overturns the old no-datastore/.env-config laws (AGENT.md updated). Verified live end-to-end. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
55 lines
2.3 KiB
YAML
55 lines
2.3 KiB
YAML
# Dev environment: `docker compose up` builds the app with hot reload (air) and
|
|
# mounts your host repositories in (AGENT.md §1.6). Because the app operates on
|
|
# repos that live on the host, the roots are mounted read-write.
|
|
|
|
services:
|
|
app:
|
|
build:
|
|
context: .
|
|
target: dev
|
|
env_file: .env
|
|
environment:
|
|
# Bind all interfaces INSIDE the container so the published port reaches
|
|
# it; the `ports` mapping below still keeps it localhost-only on the HOST.
|
|
- LISTEN_ADDR=0.0.0.0:8080
|
|
# HTTPS for the MCP connector (Claude Desktop only accepts https URLs).
|
|
# Certs are generated on the host with mkcert (see README/.env.example)
|
|
# and mounted read-only below.
|
|
- HTTPS_ADDR=0.0.0.0:8443
|
|
- TLS_CERT_FILE=/app/certs/localhost.pem
|
|
- TLS_KEY_FILE=/app/certs/localhost-key.pem
|
|
# SEED ONLY (first run): the scanner's roots now live in the config DB.
|
|
# This is copied into the DB the first time the app starts with an empty DB.
|
|
- GIT_REPO_ROOTS=/repos
|
|
# Config store (forges, project dirs, git identity) on the PRIVATE volume
|
|
# below — not bind-mounted into the project, no network port (§1.3).
|
|
- GITMANAGER_DB=/data/gitmanager.db
|
|
ports:
|
|
- "127.0.0.1:8080:8080"
|
|
- "127.0.0.1:8443:8443"
|
|
volumes:
|
|
# Source, for hot reload.
|
|
- .:/app
|
|
# Cache the Go module + build cache across restarts.
|
|
- gomod:/go/pkg/mod
|
|
# Config store — a PRIVATE named volume, deliberately NOT bind-mounted to
|
|
# the host project and NOT exposed on any port, so the credentials it holds
|
|
# are only reachable by the app inside the container (§1.3).
|
|
- gmdata:/data
|
|
# Your repositories. Set REPOS_HOST_PATH in .env (or your shell) to the
|
|
# host folder that holds them; defaults to ./repos next to this file.
|
|
- "${REPOS_HOST_PATH:-./repos}:/repos"
|
|
# --- Optional: let git authenticate to remotes from inside the container.
|
|
# Uncomment ONE approach and adjust for your host (AGENT.md §1.6, §11):
|
|
# SSH agent socket (Linux/macOS):
|
|
# - "${SSH_AUTH_SOCK}:/ssh-agent"
|
|
# or mounted keys (read-only):
|
|
# - "${HOME}/.ssh:/root/.ssh:ro"
|
|
# environment for the SSH-agent option:
|
|
# environment:
|
|
# - SSH_AUTH_SOCK=/ssh-agent
|
|
|
|
volumes:
|
|
gomod:
|
|
gmdata:
|